Arc / SECURITY

다중 레이어 E2EE 아키텍처

엔지니어링 방향을 공개하는 상용 보안 제품

ILLUSTRATED 1:1 FLOW · 10-SECOND PREVIEW

Encrypted here.Opened there.

A message between people. Private keys stay on the devices; servers carry ciphertext and delivery data.

  1. 01
    Encrypt on device

    The message is encrypted before it leaves.

  2. 02
    Transport ciphertext

    Firestore carries ciphertext and delivery data.

  3. 03
    Open on device

    The recipient’s device decrypts the message.

FunctionsExpiry & notifications
FCMPush notification

Concept animation of one delivery path, not a recording of the app. Other paths, server-visible metadata and exceptions are documented below.

ARCHITECTURE

Arc system architecture

Explore the system diagram

Private keys are stored in the device Keychain / Keystore and never sent to servers. Messages to other people are encrypted on the device before they are sent. Phoenix hands out public PreKeys, Firestore carries ciphertext, receipts and delivery data, and Cloud Functions handle expiry deletion and notifications. Mesh bypasses servers.

One role at a time.

Open full-size diagram

Devices (iOS / Android / macOS)

Arc Protocol

1:1 · libsignal v0.96.2 · Rust FFI

  • PQXDH
  • Kyber-1024
  • Double Ratchet
Private keys
Keychain / Keystore
Decrypted text
SQLite / Hive

Message text and private keys never go to servers (except AI chats, link previews)

Explore the message flows

The dots move in the numbered order. On each of these paths, message text is encrypted on the device before it is sent.

Follow one path at a time.

Open full-size diagram
1:1 message. Post-quantum. First time: fetch B's keys. Encrypt on the device. Send ciphertext only. Notify (no content). Decrypt on B's device. Read / decrypt receipts. Only A's and B's devices can read the text

Post-quantum

1:1 message

  1. First time: fetch B's keys
  2. Encrypt on the device
  3. Send ciphertext only
  4. Notify (no content)
  5. Decrypt on B's device
  6. Read / decrypt receipts

Only A's and B's devices can read the text

On smaller screens, scroll within the diagram. Open the original using the link above.

1:1 is post-quantum (PQXDH). Group messages are not (shared key + X25519 ECIES). On Mesh, nearby Arc phones may forward the ciphertext without being able to read it. Routed relay is in development.

Arc Protocol — 1:1 encryption pipeline

Phase 1

PQXDH

Key agreement with X25519 + Kyber-1024 (post-quantum)

Phase 2

Double Ratchet

A new key for every message

Phase 3

AES-256-GCM

Encrypts message bodies and media

Technology stack

Flutter 3.44
Dart
Riverpod 2.6
Rust
Arc Protocol

App

Flutter 3.44 / Riverpod 2.6 / Rust FFI (libsignal v0.96.2)

Elixir
Phoenix
Cloud Run

Key distribution API

Elixir / Phoenix on Google Cloud Run (europe-west1)

Authentication
Firestore
Storage
Functions
Messaging
App Check
Crashlytics

Delivery and auth

Firebase (Auth / Firestore / Storage / Functions / FCM / App Check / Crashlytics)

Android
Kotlin
Swift

Mesh

BLE implementation (Dart + Android Kotlin + iOS Swift, in-house, beta)

Technical specifications

The four encryption layers

Arc core specification

Arc's core specification is ML-KEM-1024/PQXDH, E2EE for 1:1 and group chats, IGF, and offline Mesh. This Security page documents the scope and technical details.

01

PQXDH 키 교환

엔지니어링 방향을 공개하는 상용 보안 제품

02

Double Ratchet

엔지니어링 방향을 공개하는 상용 보안 제품

03

AES-256-GCM 암호화

엔지니어링 방향을 공개하는 상용 보안 제품

04

XEdDSA 서명 (libsignal)

엔지니어링 방향을 공개하는 상용 보안 제품

ML-KEM-1024 파라미터

POST-QUANTUM

NIST FIPS 203 표준화 양자 내성 키 캡슐화 메커니즘.

알고리즘ML-KEM-1024 (via libsignal-client)
NIST 보안 레벨Security category 5
클래식 보안2^128 bit (X25519)
양자 보안NIST security category 5
기반Module Lattice (FIPS 203)
공개 키 크기1,568 bytes
비밀 키 크기3,168 bytes
암호문 크기1,568 bytes

컴플라이언스 & 표준

NIST CSF 2.0

NIST 프레임워크. 6개 기능으로 사이버 리스크를 체계적으로 관리.

NIST SP 800-53

연방 보안 통제. FedRAMP 기반.

FIPS 140-3

엔지니어링 방향을 공개하는 상용 보안 제품

NIST SP 800-175B

암호화 알고리즘 선택 가이드. FIPS 203 기반.

ISO/IEC 27001

국제 ISMS 인증. B2B/B2G 신뢰 기반.

GDPR

EU 일반 데이터 보호 규정. 세계 최고 수준의 보호 기준.

UK Cyber Essentials+

영국 정부 인증 사이버보안 인증.

NCSC Cloud Security

영국 NCSC 14원칙. 클라우드 보안 평가 기준.

미국 NIST, EU GDPR, 영국 NCSC, ISO가 공개한 지침을 참고해 설계했습니다. 인증이나 제3자 감사를 받은 것은 아닙니다.